2.1.1
Security Policy
Reporting a vulnerability
Please do not report security vulnerabilities through public GitHub issues.
Email chase@crumbls.com with a clear description of the issue, affected versions, and steps to reproduce it. If you have a proposed fix, include it in the report or as a private patch.
We will acknowledge receipt within five business days, assess the report, and coordinate a fix and disclosure timeline with you. Please allow us reasonable time to resolve the issue before sharing it publicly.
Supported versions
Security fixes are provided for the latest released version of the package. If you are using an older release, upgrade to the latest version before reporting an issue when possible.